Case Study

Connected cybersecurity underpins 24/x7 global steel manufacturing at Outokumpu


The global leader in sustainable stainless steel is using a unified Palo Alto Networks network security and secure access service edge platform to create a secure, flexible production environment. This enables Outokumpu to realise the cloud-first digital transformation and modernisation of its production plants.


In brief

Customer

Outokumpu

Organisation Size

8,500 employees; operations in almost 30 countries

Location

Helsinki, Finland

Featured Products and Services

Sustainable stainless steel

Industry

Manufacturing


Challenges

Lack of unified cybersecurity visibility. Exposure due to reliance on a patchwork of separate network security firewalls situated in different locations and countries. VPN remote connections lacked scalability and were unreliable and expensive. Unable to pivot quickly to support modern manufacturing operations.

Requirements
    • Agile, resilient SOC monitoring and response.
    • Automated SOC processes, with fewer manual interventions.
    • Scalable monitoring to support business growth.
    • Universal integration to third-party security technologies.
Solution

Palo Alto Networks portfolio comprising:
PA-Series and VM-Series Virtual Next-Generation Firewalls
Cloud-Delivered Security Services – including Threat Prevention, URL Filtering, DNS Security and WildFire
Panorama
Prisma Access

Download PDF Share

CHALLENGES

Metals manufacturing on a massive scale

Outokumpu Oyj is the European market leader in sustainable stainless steel and the second largest producer in the Americas. Headquartered in Finland, Outokumpu has 8,500 employees operating in almost 30 countries and is 15.5% owned by the Government of Finland.

“It’s likely that the car you drive, the renewable energy platform that powers your home, or even the pans you cook with use Outokumpu steel,” says Risto Mikola, Vice President, Head of IT Platforms at Outokumpu. “With more than 2 million tonnes of stainless steel produced every year, this is metal manufacturing on a massive scale. We consume up to 4% of all Finnish energy, and one production site measures almost 10 kilometres in length.”

Outokumpu has embarked on a digital transformation programme to modernise its plant floor and create secure, connected factories in more than 20 locations worldwide. One of the obstacles to this bold, imaginative strategy was a reliance on multiple fragmented and outmoded network security technologies in different locations.

This siloed security increased the risks from cyberattacks and advanced persistent threats. It also consumed considerable time and resources. Risto explains, “You can’t stop and start stainless steel production; every one of our manufacturing sites operates around the clock. We needed one complete network security platform to efficiently protect every Outokumpu location – from the largest production site to the smallest branch office. Zero Trust security is our goal.”

The dramatic increase in internet-connected devices and people accessing them created similar challenges. “The push to optimise steel manufacturing increases the risk of a cyberattack on vulnerable access points that must be protected – especially OT and IoT devices,” Risto says.

Outokumpu also wanted to reimagine the way people connect with the company. “We had overlapping physical VPN boxes – and rogue VPNs popped up frequently,” Risto continues. “As part of our cloud-first strategy, we wanted direct-to-app connectivity, reducing the attack surface without impacting performance or the user experience.”


quote

You can’t stop and start stainless steel production; every one of our manufacturing sites operates around the clock. We needed one complete network security platform to efficiently protect Outokumpu.

— Risto Mikola,
Vice President, Head of IT Platforms, Outokumpu Oyj

REQUIREMENTS

A trusted, all-in-one security partner

Outokumpu’s vision was to deploy a unified, best-in-class portfolio of security technologies from one trusted vendor. To achieve this, they required a portfolio that would:

  • Ensure continuous, uninterrupted manufacturing in Europe, the Americas, and elsewhere.
  • Secure a cloud-first, digital transformation and modernisation of interconnected production plants, factories, and critical supply chains.
  • Provide complete visibility into every type of network threat.
  • Protect Outokumpu’s hybrid workforce while providing exceptional user experiences.
  • Leverage in-line deep learning to stop unknown zero-day attacks.

SOLUTION

Accelerated return on manufacturing investments

Outokumpu has deployed the connected Palo Alto Networks portfolio to underpin secure digital transformation across its global operations. Machine learning (ML)-Powered Physical Next-Generation Firewalls (NGFWs), VMSeries Virtual NGFWs – via the Software NGFW Credits – a connected suite of Cloud-Delivered Security Services (CDSS), Panorama, and Prisma Access reduce the risk of downtime, accelerate the return on manufacturing investments and enhance the user experience.

This innovative implementation includes:

Network Security

The Physical and VM-Series virtual firewalls are ML-Powered NGFWs; deployed in Outokumpu’s manufacturing plants and across their global network of regional offices, they enable the company to stay ahead of complex threats. Risto’s team has instant, complete visibility into threats, deep learning analyses data, and zero-delay signatures which provide updates in seconds.

Panorama network security management helps Risto and his team save time and reduce complexity with centrally managed device lifecycle, network security configuration, and network traffic examination in one unified UI.

A connected suite of natively integrated CDSS complements the firewalls. “Cloud-Delivered Security Services as integral security in the Palo Alto Networks NGFW platform make perfect sense. Instead of using point solutions from different vendors, we benefit from one consolidated platform to secure our network traffic. WildFire, for example, gives us cloud-based malware visibility and prevention without having to add another device,” explains Risto.

The CDSS services used by Outokumpu include:

  • Advanced Threat Prevention
  • URL Filtering
  • WildFire
  • DNS Security

Secure access service edge

Prisma Access replaces the physical VPN devices, protecting more than 3,000 hybrid employees and reducing the attack surface. “Prisma Access is light years ahead of the old VPN devices – and less expensive too,” explains Risto. “It ensures all traffic is secure and there’s no impact on performance or the user experience. What’s more, it provides consistent visibility into how people access data and the data itself.”


quote

Prisma Access is light years ahead of the old VPN devices – and less expensive too. What’s more, it provides consistent visibility into how people access data and the data itself.

— Risto Mikola,
Vice President, Head of IT Platforms, Outokumpu Oyj

BENEFITS

Security that’s as strong as steel

This modern cybersecurity strategy is helping Outokumpu to accelerate digital transformation, reduce risk, and drive manufacturing efficiency. The benefits include:

  • Improved manufacturing production stability: The Palo Alto Networks portfolio prevents attacks while consistently securing users, applications, and data – wherever in Outokumpu’s global manufacturing supply chain they reside. Using the NGFWs, for example, Outokumpu can identify the exact applications running on the network and implement protective policy controls.
  • Reduced complexity and risk: By standardising on a single, connected cybersecurity portfolio, Outokumpu relieves the burden of managing multiple point security products. The organisation has “single-pane-ofglass” visibility into security, significantly reducing management complexity and risk.
  • Reduced costs: The new environment is managed by a lean Outokumpu security operations team, with automation taking care of low-level alerts and other everyday processes. There are fewer siloed security technologies to manage and licence. Moreover, there are the opportunity cost savings from avoiding downtime due to ransomware and targeted attacks. Outokumpu also has the flexibility to reduce network inefficiencies and prioritise critical traffic.
  • Seamless scalability: The intelligent cybersecurity portfolio scales in line with Outokumpu’s growth. The old VPN technology struggled to scale without significant investment, but Prisma Access secures at cloud scale while delivering true multitenancy.
  • Manufacturing supply chain protection: Suppliers and partners can connect remotely and securely to data and applications – with Outokumpu maintaining complete control and visibility throughout.

With geopolitical turmoil and change taking place on Outokumpu’s Finnish doorstep, Palo Alto Networks also ensures the manufacturer is protected against every type of known and unknown threat. Mikola explains, “We are always conscious of the evolving threats facing Finland and the wider world. With Palo Alto Networks, we can conquer every security challenge.”


quote

We are always conscious of the evolving threats facing Finland and the wider world. With Palo Alto Networks, we can conquer every security challenge.

— Risto Mikola,
Vice President, Head of IT Platforms, Outokumpu Oyj

Discover the power of the Palo Alto Networks portfolio here.

For more information, visit us online and discover how other customers are partnering with Palo Alto Networks to secure their own digital transformation.